Skip to content
CortexDocs
Deployment · Managed devices

Deploy Defender on managed macOS and Windows devices

Deploy Defender to managed macOS and Windows devices with organization onboarding, MDM installation, pilot validation, fleet operations, and removal.

Prepare deployment
  • Admin onboardingCreate the organization and installer
  • IT distributionDeploy with your device management system
  • Pilot firstValidate activity sync before fleet rollout
Your device, connected to Cortex
Supported sources
Browser
CLI
MCP
Cortex Defender Home and connected appsManage devices in Cortex
Workspace
Synced telemetryVerify capture.
Then verify sync.
Cortex Defender connects supported AI tools on your device. Verify local capture and workspace sync separately.

For Cortex organization admins and IT teams deploying Defender to managed macOS and Windows devices. This guide covers organization onboarding, MDM distribution, pilot validation, fleet operations, and removal. To choose a different operating context, see Choose a Cortex deployment. Employees use Set up Defender after the endpoint application appears on their managed device.

  • JamfmacOS distribution
  • Microsoft IntuneWindows distribution

Who owns each step

OwnerResponsibility
Chaos LabsCreate the organization and designate the initial admin with your team
Organization adminComplete organization onboarding, download installers, and coordinate Cortex access
IT or device adminDeploy Cortex Defender and manage device, keychain, network, process, and operating-system policies
EmployeeSign in, enable approved capture surfaces, and verify activity
DeveloperResolve conflicts between local services and Cortex ports

One person may fill both admin and IT roles. Cortex roles do not grant operating-system or MDM access.

Before deployment

Chaos Labs creates your organization and designates an initial admin; organization creation is not self-service.

Confirm that the organization has completed any required employee notice or consent process for monitored AI activity. Contact the Chaos Labs team if the organization needs a description of what Cortex captures.

Get the installer

Sign in as the designated admin

  1. Go to cortex.chaoslabs.xyz.
  2. Sign in with the account designated during organization creation.
  3. Complete organization onboarding.
  4. Confirm the organization and identity settings before distributing Cortex Defender.

If the designated admin cannot access the organization, contact the Chaos Labs team before distributing a package or creating another organization.

Obtain the deployment package

The onboarding flow provides the installer for each operating system:

PlatformRequirementPackageTested deployment method
macOSApple Silicon and macOS 12 or later.pkgJamf
WindowsWindows 10 or 11 on x64.exeMicrosoft Intune
Get the signed Cortex Defender installerOpen in Cortex

The installers are signed; the macOS package is also notarized. Pilot any deployment method not listed above before rollout.

Distribute the installer provided during organization onboarding. Cortex does not have a public download page.

Compare the download's SHA-256 checksum with the installer dialog before distributing it:

  • macOS: shasum -a 256 Cortex.pkg
  • Windows: Get-FileHash Cortex.exe -Algorithm SHA256

If the checksum does not match exactly, discard the download and download it again.

Distribute with MDM

Deployment steps depend on your MDM:

  1. Add the Cortex .pkg or .exe to the MDM.
  2. Assign it to a pilot group of representative devices.
  3. Apply the operating-system, keychain, routing, certificate, and network policies required for the capture paths in your rollout.
  4. Confirm Cortex Defender installs and opens without requiring the employee to run a separate installer.
  5. Restart the device after installation when practical. A restart is not normally required, but it can activate newly installed capture services and application settings.
  6. Provide employees with the organization domain and Set up Cortex Defender.

Cortex Defender can be installed on the macOS and Windows versions listed above. Capture-path availability differs by platform. Use Supported AI tools to choose what to test. Some browsers, desktop apps, command-line tools, and MCP hosts must restart after installation or configuration.

Validate a pilot device

Use at least one representative managed device for each target platform:

  1. Confirm MDM installed Cortex Defender and an employee can open it.
  2. Complete Set up Cortex Defender, including verification of every source in the rollout.
  3. Confirm the synced activity appears for an authorized Cortex user.
  4. Restart any applications named by Cortex, then confirm their capture paths become active.
  5. Quit and restart Cortex Defender, then verify capture and sync recover.

Expand the rollout only after these checks pass. Installation and Running status alone do not prove capture works.

Enrollment issues

If Cortex finds no identity providers, confirm that the employee entered the correct organization domain. The organization admin should verify the identity settings.

If sign-in does not complete, send the organization domain, identity provider, work account, and approximate attempt time to the Chaos Labs team.

Managed-device issues

Browser capture may require permission to change routing or certificate trust. Organization Admin access cannot override keychain, certificate-store, endpoint-security, or device-management policy.

If a Defender error names a local port or process, include those details when contacting the Chaos Labs team. Developers running local services can use Fix Cortex Defender port conflicts.

Rollout and fleet operations

Fleet is limited to organization admins. Use it to:

  • Filter endpoints by All endpoints, Capturing, No recent capture, Inactive, Unknown, or Needs attention.
  • Check Last contact and Last captured for stale endpoints, then inspect Diagnostics and State for supporting evidence and the current verdict.
  • Select Get installer to reopen the organization installer flow.
  • Refresh the view after a deployment or repair.
Enrolled devices and their sync statusOpen in Cortex

Enrollment and revocation happen outside Fleet. Contact the Chaos Labs team for revocation or other device-lifecycle actions that are not available in Cortex.

Offboard or replace a device

For organization offboarding or service termination:

  1. Export your organization's Cortex data during the service term or within 30 days after termination.
  2. Resolve any unsynced local backlog before removing Cortex Defender.
  3. On each device, open Connections → Browser settings.
  4. Turn off Web routing and Certificate trust to remove browser routing and certificate trust.
  5. Turn Defender off from Home and wait for Direct connection confirmed.
  6. Remove Cortex Defender through MDM or the approved device-management path.

Quitting the app is not a substitute for disconnecting it. Confirm direct connections and remove certificate trust before uninstalling.

After the 30-day export window, Cortex data may be irretrievably erased.

See Pause and stop capture for capture controls.

Contact the Chaos Labs team before removing a device that has an unsynced backlog or cannot be disconnected normally.

Was this helpful?